{"api_version":"1","generated_at":"2026-07-28T04:31:10+00:00","cve":"CVE-2026-64436","urls":{"html":"https://cve.report/CVE-2026-64436","api":"https://cve.report/api/cve/CVE-2026-64436.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64436","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64436"},"summary":{"title":"net: af_key: initialize alg_key_len for IPComp states","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x->calg and copying only the algorithm name:\n\n\tx->calg = kmalloc_obj(*x->calg);\n\tif (!x->calg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x->calg->alg_name, a->name);\n\tx->props.calgo = sa->sadb_sa_encrypt;\n\nUnlike the authentication (x->aalg) and encryption (x->ealg) branches of\nthe same function, the compression branch never initializes\ncalg->alg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg->alg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x->calg = xfrm_algo_clone(orig->calg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n  Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x10e/0x1f0\n   print_report+0xf7/0x600\n   kasan_report+0xe4/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x44/0x60\n   xfrm_state_migrate+0x70a/0x1da0\n   xfrm_migrate+0x753/0x18a0\n   xfrm_do_migrate+0xb47/0xf10\n   xfrm_user_rcv_msg+0x411/0xb50\n   netlink_rcv_skb+0x158/0x420\n   xfrm_netlink_rcv+0x71/0x90\n   netlink_unicast+0x584/0x850\n   netlink_sendmsg+0x8b0/0xdc0\n   ____sys_sendmsg+0x9f7/0xb90\n   ___sys_sendmsg+0x134/0x1d0\n   __sys_sendmsg+0x16d/0x220\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\n  Allocated by task 9287:\n   kasan_save_stack+0x33/0x60\n   kasan_save_track+0x14/0x30\n   __kasan_kmalloc+0xaa/0xb0\n   pfkey_add+0x2652/0x2ea0\n   pfkey_process+0x6d0/0x830\n   pfkey_sendmsg+0x42c/0x850\n   __sys_sendto+0x461/0x4b0\n   __x64_sys_sendto+0xe0/0x1c0\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  The buggy address belongs to the object at ff11000025a74980\n   which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes inside of\n   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg->alg_key_len to 0, matching the aalg/ealg branches.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:28","updated_at":"2026-07-27 05:16:50"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d","name":"https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb","name":"https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","name":"https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69","name":"https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0","name":"https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b","name":"https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd","name":"https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e","name":"https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64436","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64436","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f 58e82fc3dedb57b1432292504415b224fd2d6acb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f 01b9115b55018123ef2449ac4951f89147a8428e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f 3f63d1752d90c0e28be931a48ab5d89bc97d637d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f 273c06b81d2e902b21acc801ae18c8276c8a9b69 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f 6de2a650917bedaaefd65b17cede83c5e2c1dedd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f e8417353cbd078d10531ba3928e609c84ab09e6b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80c9abaabf4283f7cf4a0b3597cd302506635b7f d129c3177d7b1138fd5066fcc63a698b3ba415b0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.21","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.21 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.96 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64436","cve":"CVE-2026-64436","epss":"0.001190000","percentile":"0.021210000","score_date":"2026-07-27","updated_at":"2026-07-28 00:07:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"58e82fc3dedb57b1432292504415b224fd2d6acb","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"01b9115b55018123ef2449ac4951f89147a8428e","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"3f63d1752d90c0e28be931a48ab5d89bc97d637d","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"273c06b81d2e902b21acc801ae18c8276c8a9b69","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"6de2a650917bedaaefd65b17cede83c5e2c1dedd","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"e8417353cbd078d10531ba3928e609c84ab09e6b","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"},{"lessThan":"d129c3177d7b1138fd5066fcc63a698b3ba415b0","status":"affected","version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.21"},{"lessThan":"2.6.21","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.96","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.96","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"2.6.21","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"2.6.21","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x->calg and copying only the algorithm name:\n\n\tx->calg = kmalloc_obj(*x->calg);\n\tif (!x->calg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x->calg->alg_name, a->name);\n\tx->props.calgo = sa->sadb_sa_encrypt;\n\nUnlike the authentication (x->aalg) and encryption (x->ealg) branches of\nthe same function, the compression branch never initializes\ncalg->alg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg->alg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x->calg = xfrm_algo_clone(orig->calg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n  Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x10e/0x1f0\n   print_report+0xf7/0x600\n   kasan_report+0xe4/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x44/0x60\n   xfrm_state_migrate+0x70a/0x1da0\n   xfrm_migrate+0x753/0x18a0\n   xfrm_do_migrate+0xb47/0xf10\n   xfrm_user_rcv_msg+0x411/0xb50\n   netlink_rcv_skb+0x158/0x420\n   xfrm_netlink_rcv+0x71/0x90\n   netlink_unicast+0x584/0x850\n   netlink_sendmsg+0x8b0/0xdc0\n   ____sys_sendmsg+0x9f7/0xb90\n   ___sys_sendmsg+0x134/0x1d0\n   __sys_sendmsg+0x16d/0x220\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\n  Allocated by task 9287:\n   kasan_save_stack+0x33/0x60\n   kasan_save_track+0x14/0x30\n   __kasan_kmalloc+0xaa/0xb0\n   pfkey_add+0x2652/0x2ea0\n   pfkey_process+0x6d0/0x830\n   pfkey_sendmsg+0x42c/0x850\n   __sys_sendto+0x461/0x4b0\n   __x64_sys_sendto+0xe0/0x1c0\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  The buggy address belongs to the object at ff11000025a74980\n   which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes inside of\n   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg->alg_key_len to 0, matching the aalg/ealg branches."}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-27T05:00:57.092Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb"},{"url":"https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e"},{"url":"https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d"},{"url":"https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69"},{"url":"https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd"},{"url":"https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b"},{"url":"https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e"},{"url":"https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0"}],"title":"net: af_key: initialize alg_key_len for IPComp states","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64436","datePublished":"2026-07-25T08:51:10.370Z","dateReserved":"2026-07-19T15:36:31.787Z","dateUpdated":"2026-07-27T05:00:57.092Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:28","lastModifiedDate":"2026-07-27 05:16:50","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64436","Ordinal":"1","Title":"net: af_key: initialize alg_key_len for IPComp states","CVE":"CVE-2026-64436","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64436","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x->calg and copying only the algorithm name:\n\n\tx->calg = kmalloc_obj(*x->calg);\n\tif (!x->calg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x->calg->alg_name, a->name);\n\tx->props.calgo = sa->sadb_sa_encrypt;\n\nUnlike the authentication (x->aalg) and encryption (x->ealg) branches of\nthe same function, the compression branch never initializes\ncalg->alg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg->alg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x->calg = xfrm_algo_clone(orig->calg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n  Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x10e/0x1f0\n   print_report+0xf7/0x600\n   kasan_report+0xe4/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x44/0x60\n   xfrm_state_migrate+0x70a/0x1da0\n   xfrm_migrate+0x753/0x18a0\n   xfrm_do_migrate+0xb47/0xf10\n   xfrm_user_rcv_msg+0x411/0xb50\n   netlink_rcv_skb+0x158/0x420\n   xfrm_netlink_rcv+0x71/0x90\n   netlink_unicast+0x584/0x850\n   netlink_sendmsg+0x8b0/0xdc0\n   ____sys_sendmsg+0x9f7/0xb90\n   ___sys_sendmsg+0x134/0x1d0\n   __sys_sendmsg+0x16d/0x220\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\n  Allocated by task 9287:\n   kasan_save_stack+0x33/0x60\n   kasan_save_track+0x14/0x30\n   __kasan_kmalloc+0xaa/0xb0\n   pfkey_add+0x2652/0x2ea0\n   pfkey_process+0x6d0/0x830\n   pfkey_sendmsg+0x42c/0x850\n   __sys_sendto+0x461/0x4b0\n   __x64_sys_sendto+0xe0/0x1c0\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  The buggy address belongs to the object at ff11000025a74980\n   which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes inside of\n   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg->alg_key_len to 0, matching the aalg/ealg branches.","Type":"Description","Title":"net: af_key: initialize alg_key_len for IPComp states"}]}}}